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IN THE CLAIMS 
Please amend the claims as follows: 

1 . (Currently Amended) A remote-access VPN mediating method in a system 
wherein: VPN client units and a VPN gateway unit are connected to an IP network; 
communication units are connected to a local area network placed under the management of 
the VPN gateway unit; and a remote-access VPN by a tunneling protocol is implemented 
between an arbitrary one of the VPN client units and the VPN gateway unit connected to said 
IP network and an arbitrary one of the communication units connected to the local area 
network placed under the management of the VPN gateway unit, where VPN represents 
virtual private network, said method comprising the steps of: 

(a) sending an access control list containing information indicative of a private IP 
address assigned to said communication unit to a mediating apparatus on said IP network 
from said VPN gateway unit , said mediating apparatus being a separate and distinct apparatus 
from the VPN gateway unit ; 

(b) storing said access control list in said mediating apparatus in correspondence to 
said VPN gateway unit; 

(c) retrieving, by said mediating apparatus, an IP address of said VPN gateway unit in 
response to a request from said VPN client unit, acquiring the private IP address of the 
corresponding communication unit from said access control list, sending the acquired IP 
address of said VPN gateway unit and the acquired private IP address to said VPN client unit, 
sending an IP address of said VPN client unit to said VPN gateway unit, generating mutual 
authentication information for setting up an authenticated encrypted tunnel between said 
VPN client unit and said VPN gateway unit, and sending said mutual authentication 
information to both of said VPN client unit and said VPN gateway unit; and 
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(d) setting up said authenticated encrypted tunnel between said VPN client unit and 
said VPN gateway unit by use of said mutual authentication information, and implementing 
remote access through said encrypted tunnel by use of the private IP address of said 
communication unit. 

2. (Original) The remote-access mediating method of claim 1, wherein said access 
control list contains attribute information about said VPN client unit. 

3. (Original) The remote-access VPN mediating method of claim 2, wherein said 
step (a) includes a step of encrypting a communication channel between said mediating 
apparatus and said VPN gateway unit or a VPN gateway management unit having an 
authority of its management, and sending said access control list from said VPN gateway unit 
to said mediating apparatus. 

4. (Previously Presented) The remote-access VPN mediating method of claim 2 or 3, 
wherein said step (b) includes steps of: 

authenticating said VPN gateway unit by said mediating apparatus; and 
storing said access control list for said VPN client unit sent from said VPN gateway 
unit when the authentication is successful. 

5. (Previously Presented) The remote-access VPN mediating method of claim 2 or 3, 
wherein said step (c) includes the steps of: 

(c-0) on receiving a request for retrieval of an IP address assigned to said VPN 
gateway unit from said VPN client unit, verifying whether said VPN client unit has an 
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authority of access to said VPN gateway unit; and only when said VPN client unit has said 

access authority, 

(c-1) referring to said access control list, and acquiring the private IP address assigned 
to said communication unit; 

(c-2) searching a domain name server to acquire the IP address assigned to said VPN 
gateway unit; 

(c-3) generating said mutual authentication information for authentication between 
said VPN client unit and said VPN gateway unit; 

(c-4) encrypting a first communication channel between said mediating apparatus and 
said VPN client unit, and sending said mutual authentication information, the IP address of 
said VPN gateway unit and the private IP address of said communication unit to said VPN 
client unit; 

(c-5) encrypting a second communication channel between said mediating apparatus 
and said VPN gateway unit, and sending to said VPN gateway unit said mutual authentication 
information, an IP address of said VPN client unit and said attribute information about said 
VPN client unit described in said access control list. 

6. (Original) The remote-access VPN mediating method of claim 5, comprising the 

steps: 

wherein, at the time of setting up the encrypted tunnel between said VPN client unit 
and said VPN gateway unit, said VPN gateway unit performs at least one of: a function of 
determining the private IP address to be given to said VPN client unit on the basis of said 
attribute information on said VPN client unit sent from said mediating apparatus, and giving 
the determined private IP address to said VPN client unit; a function of determining a VLAN 
to be accommodated on the basis of said attribute information about said VPN client unit, a 
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gateway address, an internal DNS address, a WINS server address, etc.; and a function of 
changing packet filtering setting of said VPN gateway unit on the basis of said attribute 
information; and 

wherein when the tunnel established between said VPN gateway unit and said VPN 
client unit is disconnected or no communication has been conducted via said tunnel for a 
predetermined period of time, said VPN gateway unit performs tunnel cleanup processing, 
processing for returning the private IP address assigned to said VPN client unit, and restoring 
the setting of the packet filtering of said VPN gateway unit used for said VPN client unit 
concerned. 

7. (Previously Presented) The remote-access VPN mediating method of claim 2 or 3, 
wherein: letting a domain name server be denoted by DNS, said step (c) includes a step 
wherein said VPN client unit captures a DNS query transferred from an in-unit application or 
another VPN client unit, then collates the source address and contents of said query with 
filtering conditions, and, if they match the conditions, converts said query to a query to said 
mediating apparatus; said step (d) includes a step of setting/updating tunneling protocol 
configuration management information on the basis of an answer to said query; and said step 
(e) includes a step of initializing the tunnel as required, passing the private IP address of the 
communication unit specified by said mediating unit, as the result of said DNS query, to the 
application of the query source. 

8. (Previously Presented) The remote-access VPN mediating method of claim 5, 
wherein, letting simple public key infrastructure be denoted by SPKI, said step (c) includes a 
step wherein said VPN client unit issues a certificate by an SPKI scheme, and another VPN 
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client unit having received said certificate sends to said mediating apparatus a request for 

retrieval of the IP address assigned to said VPN gateway unit. 

9. (Currently Amended) A remote-access VPN mediating apparatus which is built on 
an IP network to implement a remote-access VPN representing virtual private network in a 
system wherein: VPN client units and a VPN gateway unit are connected to the IP network; 
communication units are connected to a local area network placed under the management of 
the VPN gateway unit; and a remote-access VPN by a tunneling protocol is implemented 
between an arbitrary one of said VPN client units and said VPN gateway unit connected to 
said IP network and an arbitrary one of said communication units connected to said local area 
network placed under the management of said VPN gateway unit, said apparatus being a 
separate and distinct apparatus from the gateway unit and comprising: 

ACL storage means for storing an access control list, hereinafter referred to as ACL, 
sent from said VPN gateway unit and containing information indicative of a private IP 
address assigned to said communication unit; 

authentication/access authorization control means for authenticating said VPN client 
unit and said VPN gateway unit, and for executing access authorization control; 

IP address acquiring means for referring to said access control list to acquire the 
private IP address assigned to said communication unit, and for searching a domain name 
server to acquire an IP address assigned to said VPN gateway unit; 

authentication information generating means for generating mutual authentication 
information for setting up an authenticated encrypted tunnel between said VPN client unit 
and said VPN gateway unit; and 

communication means for sending the IP address of said VPN gateway unit, the 
private IP address of said communication unit and said mutual authentication information to 



6 



Application No. 10/526,935 

Reply to Office Action of January 15, 2009, and Advisory Action dated April 29, 2009 

said VPN client unit, and for sending the IP address of said VPN client unit and said mutual 

authentication information to said VPN gateway unit. 

10. (Original) The mediating apparatus of claim 9, wherein said communication 
means includes encryption means for encrypting communications between said mediating 
apparatus and said VPN client unit, and communications between said mediating apparatus 
and said VPN gateway unit. 

1 1 . (Previously Presented) The mediating apparatus of claim 9, wherein said 
authentication/access authorization control means is configured to: 

authenticate said VPN client unit; and only when the authentication is successful, 
cause said IP address acquiring means to query the domain name server about the IP address 
assigned to said VPN gateway unit and acquire said IP address; cause said mutual 
authentication information generating means to generate said mutual authentication 
information; and cause said communication means to send the acquired IP address, the 
private IP address assigned to said communication unit, and said generated mutual 
authentication information to said VPN client unit. 

12. (Previously Presented) The mediating apparatus of claim 9, wherein said 
authentication/access authorization control means is configured to: 

decide whether said VPN client unit has the authority to retrieve the IP address 
assigned to said VPN gateway unit; and only when the VPN client unit has said authority, 
cause said IP address acquiring means to query the domain name server about the IP address 
assigned to said VPN gateway unit and acquire said IP address; cause said mutual 
authentication information generating means to generate said mutual authentication 
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information; and cause said communication means to send the acquired IP address, the 
private IP address assigned to said communication unit, and said generated mutual 
authentication information to said VPN client unit. 

13. (Previously Presented) The mediating apparatus of claim 1 1 or 12, wherein said 
authentication/access authority control means is configured to: 

authenticate said VPN gateway unit; and only when the authentication is successful, 
causes said communication means to send the IP address assigned to said VPN client unit and 
said mutual authentication information to said VPN gateway unit. 

14. (Previously Presented) The mediating apparatus of claim 9, wherein said 
authentication/access authorization control means is configured to authenticate said VPN 
client unit and said VPN gateway unit by an SPKI (Simple Public Key Infrastructure) 
scheme, and/or executes access authorization control. 

15. (Previously Presented) The mediating apparatus of claim 9, wherein said 
authentication/access authorization control means authenticates said VPN client unit and said 
VPN gateway unit by a PKI (Public Key Infrastructure) scheme.. 
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